The "stringprep" module didn't process characters from RFC 3454 tables B.2 or B.3 correctly: the latest Unicode codepoint attributes were used instead of the specified Unicode 3.2.0. This behavior would cause mismatches when processing domain names using IDNA 2003 (the "idna" codec) and the in_table_b2() function of the "stringprep" module. This only affects domain names containing characters that were not previously registered or had their Unicode attributes such as case-folding behavior updated since Unicode 3.2.0.
https://mail.python.org/archives/list/[email protected]/thread/EUHHTC6EV7HCLSUHP25C5VHSV4V2MUZN/
https://github.com/python/cpython/pull/155293
https://github.com/python/cpython/issues/155292
https://github.com/python/cpython/commit/7e109d084d55e7eb25837a5f3b47ef9beee547bc
https://github.com/python/cpython/commit/5181304bcec9cfc3c15311741c9154cdff2e3fd7
Published: 2026-08-18
Updated: 2026-08-19
Base Score: 5.5
Vector: CVSS2#AV:N/AC:L/Au:S/C:N/I:P/A:P
Severity: Medium
Base Score: 5.3
Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
Severity: Medium
Base Score: 6
Vector: CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:P/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N
Severity: Medium
EPSS: 0.00511